Executive brief
IBM Cloud Pak for Business Automation is an enterprise automation platform used to streamline business processes. An authenticated user can trigger a denial of service condition that exhausts server resources (CPU and memory), causing the service to become unavailable to legitimate users.
Technical details
The vulnerability stems from uncontrolled resource consumption, likely related to one or more of the underlying dependencies (body-parser, Eclipse Parsson, or js-yaml) that fail to properly limit resource allocation during parsing or request processing. An authenticated attacker can craft malicious input—such as oversized request bodies, large JSON documents, or specially crafted YAML—that causes the application to consume excessive CPU and memory. The attack requires authentication, limiting exposure to internal or privileged users. Patches are available in the August 2026 iFixes for Cloud Pak for Business Automation.
Affected products
- IBM Cloud Pak for Business Automation
Timeline
- 2026-09-14: disclosed
- 2026-08: patched: Patches included in August 2026 iFixes